Implementing Second Factor for Single Sign-On

Answer Correct answer: B — Implement software-based TOTP to provide a second factor of authentication using a possession-based token.

A systems administrator wants to add a second factor to the single sign-on portal that the organization uses. Currently, only a username and password are required. Which of the following should the administrator implement to best meet this requirement?

  1. Personal verification questions
  2. Software-based TOTP Correct Answer
  3. Log-in image checks
  4. Secondary PIN code

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the ability to distinguish between factors of authentication (knowledge vs. possession), with the common trap being the selection of other knowledge-based methods like PINs or verification questions.

This question explores methods to enhance single sign-on security by adding a second factor. The correct approach involves implementing software-based TOTP, which provides a strong 'something you have' authentication layer.

Option D (Secondary PIN code) is frequently selected because it feels like a simple additional step; however, it remains a 'something you know' factor, failing to meet the requirement for a distinct second factor type.

Community Discussion (4 comments)

psowrong 👍 8 Selected: B
A. Personal verification questions - something you know B. Software-based TOTP - something you have C. Log-in image checks - something you know D. Secondary PIN code - something you know
LuckyAro 👍 1 Selected: D
PIN Code generally cuts across all platforms including situations where mobile phones are not allowed in secure facilities.
salah112 👍 2 Selected: B
B. Software-based TOTP To enhance security in a single sign-on portal and implement a second factor, a software-based Time-based One-Time Password (TOTP) is a strong choice. TOTP typically involves using a mobile app, such as Google Authenticator or Authy, to generate a time-sensitive code that serves as the second factor in addition to the username and password.
Hs1208 👍 2
B. Software-based TOTP(something you have)

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The implementation of a second factor requires Multi-Factor Authentication (MFA), which mandates combining at least two different categories: something you know, something you have, or something you are. Software-based TOTP (Time-based One-Time Password) utilizes an authenticator app on a mobile device to generate dynamic codes. This qualifies as "something you have," effectively creating a second factor when combined with the existing username and password.

Why the Other Options Are Wrong

Options A (Personal verification questions), C (Log-in image checks), and D (Secondary PIN code) all rely on static information that the user memorizes. These fall under the "something you know" category. Since the system already uses a password (also "something you know"), adding another knowledge-based factor does not increase security against credential theft or phishing in the same way possession-based factors do.

Community Comment Notes

Community consensus strongly supports Option B, with users noting that TOTP represents the "something you have" factor. As noted by user psowrong, "A. Personal verification questions - something you know B. Software-based TOTP - something you have." Another commenter, LuckyAro, attempted to justify a PIN but was outvoted, highlighting the standard definition of MFA factors.

Exam Strategy

When asked about adding a second factor, always look for options that introduce a new authentication domain (possession or biometrics). If the current method is knowledge-based (password), avoid selecting other knowledge-based additions like PINs or security questions.

Frequently Asked Questions

Why is a secondary PIN code not considered a second factor?

A secondary PIN is still 'something you know.' MFA requires two distinct categories, so adding another knowledge factor does not meet the strict definition.

What is the difference between TOTP and SMS OTP?

TOTP is generated locally on an app (Google Authenticator), while SMS relies on network transmission. Both are 'something you have,' but TOTP is generally more secure against SIM swapping.

Related Analysis

← Back to SY0-601 Study Guide